2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-24343HIGH7.8Artifex MuJS through 1.0.7 has a use-after-free in jsrun.c because of unconditional marking in jsgc.c.
CVE-2020-24342HIGH7.8Lua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because a protection mechanism wrongly calls luaD_ca...
CVE-2020-24332MEDIUM5.5An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the creation of ...
CVE-2020-24331HIGH7.8An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the tss user sti...
CVE-2020-24330HIGH7.8An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges instead of by the...
CVE-2020-17498MEDIUM6.5In Wireshark 3.2.0 to 3.2.5, the Kafka protocol dissector could crash. This was addressed in epan/dissectors/packet-kafk...
CVE-2020-0261HIGH7.8In C2 flame devices, there is a possible bypass of seccomp due to a missing configuration file. This could lead to local...
CVE-2020-14483MEDIUM4.3A timeout during a TLS handshake can result in the connection failing to terminate. This can result in a Niagara thread ...
CVE-2020-15947HIGH8.8A SQL injection vulnerability in the qm_adm/qm_export_stats_run.do endpoint of Loway QueueMetrics before 19.10.21 allows...
CVE-2020-15925HIGH8.8A SQL injection vulnerability at a tpf URI in Loway QueueMetrics before 19.10.21 allows remote authenticated attackers t...
CVE-2020-13286MEDIUM4.3For GitLab before 13.0.12, 13.1.6, 13.2.3 user controlled git configuration settings can be modified to result in Server...
CVE-2020-13281MEDIUM6.5For GitLab before 13.0.12, 13.1.6, 13.2.3 a denial of service exists in the project import feature
CVE-2020-11733MEDIUM6.7An issue was discovered on Spirent TestCenter and Avalanche appliance admin interface firmware. An attacker, who already...
CVE-2020-17463CRITICAL9.8FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.
CVE-2020-16087HIGH8.6An issue was discovered in Zalo.exe in VNG Zalo Desktop 19.8.1.0. An attacker can run arbitrary commands on a remote Win...
CVE-2020-13285MEDIUM5.4For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting (XSS) vulnerability exists in the issue reference numbe...
CVE-2020-13283MEDIUM5.4For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting vulnerability exists in the issues list via milestone t...
CVE-2020-13282LOW3.5For GitLab before 13.0.12, 13.1.6, 13.2.3 after a group transfer occurs, members from a parent group keep their access l...
CVE-2020-13280MEDIUM6.5For GitLab before 13.0.12, 13.1.6, 13.2.3 a memory exhaustion flaw exists due to excessive logging of an invite email er...
CVE-2020-4589CRITICAL9.8IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the s...
CVE-2020-8720MEDIUM5.5Buffer overflow in a subsystem for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 m...
CVE-2020-8689MEDIUM6.5Improper buffer restrictions in the Intel(R) Wireless for Open Source before version 1.5 may allow an unauthenticated us...
CVE-2020-8688HIGH7.5Improper input validation in the Intel(R) RAID Web Console 3 for Windows* may allow an unauthenticated user to potential...
CVE-2020-8687HIGH7.8Uncontrolled search path in the installer for Intel(R) RSTe Software RAID Driver for the Intel(R) Server Board M10JNP2SB...
CVE-2020-8685MEDIUM4.4Improper authentication in subsystem for Intel (R) LED Manager for NUC before version 1.2.3 may allow privileged user to...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now